Discovery, mapping, and inventory of your IT assets

You cannot protect what you do not know. Comprehensive and continuous mapping of your IT infrastructure is the foundation of any cybersecurity strategy. Cyberwatch automatically discovers and inventories all your assets: endpoints, cloud, OT, external surface, and software libraries.

Shadow IT: the blind spot in your security

Most organizations only know a fraction of their IT assets. Forgotten servers, orphaned VMs, unlisted cloud instances, undocumented network equipment, exposed subdomains, and uninventoried software dependencies: this shadow IT represents an invisible and unprotected attack surface.

Without a comprehensive and up-to-date inventory, your vulnerability scans only cover a fraction of your actual exposure. Attackers, however, target exactly what you cannot see.

Shadow IT Mapping

Shadow IT / OT

Unlisted devices connected to the network without oversight act as invisible entry points for attackers.

Outdated manual inventories

Excel files and self-reported inventories never reflect the reality on the ground. The gaps only widen with every maintenance intervention.

Strict regulations

NIS2, LPM, IEC 62443: regulations require an up-to-date inventory of critical industrial assets, complete with traceability and audit trails.

Discovery

Automated multi-perimeter discovery

Internal infrastructure

Network scans (IP ranges, reverse DNS), Active Directory integration, hypervisor connectors (VMware, Proxmox, Hyper-V, etc.). Discovery of servers, workstations, VMs, and network equipment.

Cloud and containers

API connection to cloud providers (AWS, Azure, Google Cloud, OpenStack). Automatic inventory of instances, VMs, containers, Kubernetes clusters, and image registries.

External surface

DNS enumeration, WHOIS, Certificate Transparency, and public IP scanning. Discovery of subdomains, exposed services, and unreferenced assets accessible from the Internet.

OT / Industrial systems

Native Rockwell, Schneider, and Siemens connectors. SNMP, Modbus, and S7-Comm protocols. Non-intrusive inventory of PLCs and industrial equipment.

Software libraries

SCA (Software Composition Analysis) for npm, yarn, Maven, Composer, pip, NuGet, RubyGems, and Go. Open-source component inventory and SBOM generation (CycloneDX, SPDX).

Identities and directories

Active Directory, Entra ID, Microsoft 365. Inventory of accounts, groups, delegations, GPOs, and critical permissions across your organization.

inventory

A dynamic, context-aware inventory

Continuous updates

The inventory updates with every scan. Assets that appear, disappear, or are modified are detected automatically.

  • Rockwell Automation— ControlLogix, CompactLogix, MicroLogix (via EtherNet/IP)
  • Schneider Electric— Modicon M340, M580, Premium, Quantum (via Modbus TCP)
  • Siemens— SIMATIC S7-300, S7-400, S7-1200, S7-1500 (via S7 protocol)

Business context

Organize your assets into projects and groups aligned with your priorities: production, DMZ, development, OT. Assign a CIA (Confidentiality, Integrity, Availability) criticality level to each perimeter.

  • Managed switches, routers, and industrial firewalls (Cisco, Hirschmann, Moxa, Fortinet, etc.)
  • SNMP v1/v2c/v3 polling for inventory and firmware vulnerability detection

Over 50 connectors

Cyberwatch interfaces with your existing tools: Active Directory, VMware, AWS, Azure, GCP, CMDB, Jira, ServiceNow, GLPI.

  • SCADA / DCS servers, HMI supervision stations
  • Windows and Linux operator workstations in industrial networks
  • OS and application vulnerability scanning with or without an agent, including on legacy Windows systems (Server 2008, 2012)

Dynamic groups

Create automatic filtered views by OS, location, criticality, or any other attribute. Restrict access by team.

  • SCADA / DCS servers, HMI supervision stations
  • Windows and Linux operator workstations in industrial networks
  • OS and application vulnerability scanning with or without an agent, including on legacy Windows systems (Server 2008, 2012)
Mapping Continuous Inventory

Nozomi Networks

Inventory import from Nozomi probes already deployed on your industrial networks

  • Item 1
  • Item 2
  • Item 3

Allentis (Framatome subsidiary)

Native connector with Allentis NDR probes, ANSSI-qualified, for unified IT/OT mapping

  • Item 1
  • Item 2
  • Item 3

Seckiot

Integration with Seckiot sensors to enrich the OT inventory

  • Item 1
  • Item 2
  • Item 3

Seckiot

Correlation between network data (probes) and system data (Safe Query) for a complete and deduplicated inventory

  • Item 1
  • Item 2
  • Item 3

Mapping is the foundation of all vulnerability management—it determines the effectiveness of detection, prioritization, and remediation.

reporting and API

Reporting and integrations

Cyberwatch is designed to fit into your ecosystem: export your data to your ITSM tools, feed your dashboards, connect your AI models, or industrialize your exports. Four complementary channels cover all use cases.

PDF Reports

Automatically generated executive and technical reports: overall security posture, top vulnerabilities, SLA tracking, and regulatory compliance. Customizable templates branded to your organization and scheduled exports.

API and Exports

Documented API for automating exports, CMDB integrations, and bidirectional synchronization with ServiceNow, GLPI, and Jira. CSV/JSON exports of inventory and vulnerabilities, with ready-to-use cURL and PowerShell snippets.

Dashboards and analytics

Build your dashboards directly within the software, without the need for third-party tools: indexes are documented and accessible. For advanced analysis, data can be exported to your own analytics environment or security data lake.

MCP Server

Connect Cyberwatch to any language model (Claude, GPT, Mistral, Llama, etc.) via the Model Context Protocol. Query your inventory in natural language, generate summaries, and automate your security workflows.

Testimonials

Pouvoir cartographier nos environnements sensibles sans connexion réseau permanente était une exigence non négociable. Cyberwatch répond à cette contrainte tout en gardant un inventaire à jour.

Exemple à remplacer — Officier sécurité, défense

Officier de sécurité des systèmes d'information

La cartographie automatique de nos actifs nous a permis de découvrir des serveurs oubliés que nos audits précédents n'avaient jamais identifiés. C'est un vrai gain de visibilité sur notre Shadow IT.

Exemple à remplacer — Responsable sécurité, finance

Responsable sécurité IT

FAQ

From asset mapping to automated remediation.

How does Cyberwatch automatically discover IT assets?

Cyberwatch combines several methods: network scanning and subdomain discovery to detect Shadow IT, direct queries to cloud APIs (AWS, Azure, Google Cloud), connections to existing infrastructure tools (Active Directory, LDAP, CMDB, VMware, network equipment, etc.), and native connectors for OT environments. These discovery processes run continuously, without manual intervention, to ensure your inventory is always up to date.

hidden category

Does the IT asset mapping include open-source software libraries?

Yes, Cyberwatch integrates SCA (Software Composition Analysis) to inventory the open-source components used in your development projects, including those on npm, Maven, pip, NuGet, or Go. This software inventory is complemented by the automatic generation of a Software Bill of Materials (SBOM), which is essential for regulatory compliance and the traceability of your software supply chain.

hidden category

Can Cyberwatch map industrial (OT) environments?

Yes, Cyberwatch features native connectors for Rockwell, Schneider, and Siemens PLCs via SNMP, Modbus, and S7-Comm protocols. Industrial equipment inventory is performed non-intrusively, an essential requirement in OT environments where overly aggressive scanning can disrupt critical physical processes.

hidden category

Why is an inventory of identities and directories part of IT mapping?

Identities (accounts, groups, permissions) represent an attack surface in their own right, one that is often overlooked in traditional mapping processes. Cyberwatch inventories Active Directory, Entra ID, and Microsoft 365 directories, including delegations and GPOs, to reveal poorly managed critical permissions that could lead to privilege escalation.

hidden category

How can I use Cyberwatch inventory data in my existing tools?

Cyberwatch offers four export channels: executive and technical PDF reports, a REST API to sync with your CMDBs (ServiceNow, GLPI, Jira), Elasticsearch/Kibana access for advanced dashboards, and an MCP server that lets you query your inventory in natural language using AIs like Claude, ChatGPT, or Mistral.

hidden category